Sunteți pe pagina 1din 2

3/6/2019 SAP Passport CA (root certificate) has been updated. Where to put it?

- SAP Q&A

(http://www.sap.com/)

Products (https://www.sap.com/products.html)
Industries Industries (https://www.sap.com/industries.html)

Services and Support


upport (https://www.sap.com/support.html)
Training Training (https://www.sap.com/training-certi cation.html)

Community (https://www.sap.com/community.html)
Developer Developer (https://developers.sap.com/index.html)
Partner Partner (https://www.sap.com/partner.html)

About (https://www.sap.com/corporate/en.html)

 
Ask a Question (https://answers.sap.com/questions/ask.html) Write a Blog Post (https://blogs.sap.com/wp-admin/post-new.php) Login (/users

Not what you're looking for? Search community questions.

Olegs Veliks (/users/64023/olegsveliks.html)


(/users/64023/olegsveliks.html)
SAP Passport CA (root certi cate) has been updated. Where to put it?
Mar 02, 2018 at 09:44 AM | 722 Views | Last edit Mar 07, 2018 at 08:51 PM 3 rev. (/revisions/449357.html)

Recently we’ve received information about certificates update.


https://wiki.hybris.com/ (https://goo.gl/2kFHUd)
Our scenario is 2) Outbound Communication to External Systems.
We have integration between C4C and CRM through HCI and all C4C Outbound web services are currently using SSL Client Authorization.
Judging from the above article we need to extract SSL Client Certificate and update every iFlow which is consuming C4C Outbound interface.
An unclear part is SAPPassportCA.der – root certificate. Should we install this into HCI key store or somewhere else?

SAP Cloud Platform Integration tools (/tags/67838200100800006241) SAP Cloud for Customer add-ins (/tags/01200615320800003136) | c4c integration
(/topics/c4c+integration.html)

Follow RSS Feed

Related questions
Can't retrieve data

2 Answers
Votes | Newest | Oldest

Best Answer

Shivanand Hangaragi (/users/59996/shivanandhangaragi.html)


(/users/59996/shivanandhangaragi.html)

Mar 02, 2018 at 11:51 AM

Dear Olegs Veliks (https://answers.sap.com/users/64023/olegsveliks.html),


1
Yes you are right, you need to import new SAP Passport CA into your HCI Keystore, and then download the new M-User certi cate from C4C
system(Either from Outbound Communication Arrangement OR Administrator>>Communication Certi cates>>Download Tenant
Certi cate) and upload into your IFlows(Sender channel).
Make sure to map this M-User certi cate to HCI User.
Regards,
https://answers.sap.com/questions/449357/sap-passport-ca-root-certificate-has-been-updated.html 1/2
Shi dBH
Shivanand B H
3/6/2019 SAP Passport CA (root certificate) has been updated. Where to put it? - SAP Q&A
Share

2 Comments

Shivanand Hangaragi (/users/59996/shivanandhangaragi.html)

Mar 05, 2018 at 06:10 AM (/comments/450733/view.html)


Dear Olegs Veliks (https://answers.sap.com/users/64023/olegsveliks.html),

You should be able to see a button "Download Tenant Certi cate" under Administrator>>Communication Certi cates. If you are unable to see this button, then you can raise an
incident to SAP, and in the meantime you can download it from the arrangement.
M-User certi cate is the one which download with these steps, and this is used in HCI IFlow sender channel. However considering there will be many IFlows so uploading the
certi cate to every one of them may be time consuming, hence the short cut would be assign this certi cate to an user in HCI(Manage Certi cate-to-User Mappings), and use
that user id in every IFlow. This may save you lot of time.

For this to work, you need to use "User Role" authentication mode in HCI Sender Channel, and in Externalized Parameters, provide the HCI Artifact name.
Regards,

Shivanand B H

Like 0 Share

Show all

Dennis Neubrand (/users/85892/dennisneubrand.html)


(/users/85892/dennisneubrand.html)
Apr 01, 2018 at 06:32 PM

Hi,
0 I applied the new SAP passport root CA to the HCI keystore, however all my integration scenarios from C4C to HCI fail with "401 - unauthorized"
since today. I also checked the M-certi cate from C4C, this did not change, it is still the same than half a year ago or so. Any idea what the issue
here might be?
Regards,

Dennis
Share

2 Comments

Olegs Veliks (/users/64023/olegs.veliks.html)

Apr 01, 2018 at 09:18 PM (/comments/470350/view.html)


Have you updated Sender’s certi cates? Take them from Communication Arrangement, import into iFlow sender and redeploy.

Like 0 Share

Dennis Neubrand (/users/85892/dennis.neubrand.html)

Apr 11, 2018 at 08:22 AM (/comments/478657/view.html)


yes we did this, however the sender certi cate was still the same than before. I then reported a very high incident, the result was that SAP had issues with the new certi cate, they
corrected it in HCI.

Like 0 Share

Share & Follow

(https://www.facebook.com/sapcommunity) (https://twitter.com/SAPCommunity) (https://www.youtube.com/c/SAPCommunities)

(https://www.linkedin.com/company/sap) (http://www.slideshare.net/SAP) (https://instagram.com/sap/) ()

Privacy (http://sap.com/about/legal/privacy.html) Terms of Use (http://sap.com/corporate/en/legal/terms-of-use.html)

Legal Disclosure (http://sap.com/about/legal/impressum.html) Copyright (http://sap.com/about/legal/copyright.html)

Trademark (http://sap.com/about/legal/trademark.html) Cookie Preferences

Sitemap (http://www.sap.com/sitemap/index.html) Newsletter (https://sap.com/registration/newsletter.html)

https://answers.sap.com/questions/449357/sap-passport-ca-root-certificate-has-been-updated.html 2/2

S-ar putea să vă placă și